Wednesday, 3 September

Sunday, 31 August2025

Attackers Exploit Velociraptor Forensic Tool to Create C2 Tunnel via VS Code

Attackers Exploit Velociraptor Forensic Tool to Create C2 Tunnel via VS Code
Cybersecurity experts have uncovered a sophisticated intrusion where attackers hijacked the legitimate forensic tool Velociraptor to gain remote access. Using msiexec, malware was staged from a Cloudflare Workers domain, installing Velociraptor. It then downloaded and launched Visual Studio Code with tunneling enabledcreating a covert command-and-control (C2) channel.

Subscribe To Our Newsletter.

Full Name
Email